Click here to get back home

Re: Possible hack attempt ?

 HomeNewsGroups | Search | About
 alt.www.webmaster    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Re: Possible hack attempt ? John Bokma 10-11-2008
Get Chitika Premium
Posted by John Bokma on October 11, 2008, 7:30 pm
Please log in for more thread options



> Hi Folks,
>
> Just came across this in server access log. Can anybody tell me
> what's likely to be going on with this.

MS SQL injection attempt:
http://www.f-secure.com/weblog/archives/00001427.html

Get the IP address from the log, type it after:

        http://www.spamcop.net/sc?track=

and email the address(es) returned by spamcop. If you're lucky you just
killed a zombie.

--
John Bokma http://johnbokma.com/

AISE/AWW/SEO/web development forum: http://seo-expert-wiki.com/

Posted by Neil on October 12, 2008, 5:03 am
Please log in for more thread options



>
>> Hi Folks,
>>
>> Just came across this in server access log. Can anybody tell me
>> what's likely to be going on with this.
>
> MS SQL injection attempt:
> http://www.f-secure.com/weblog/archives/00001427.html
>
> Get the IP address from the log, type it after:
>
> http://www.spamcop.net/sc?track=
>
> and email the address(es) returned by spamcop. If you're lucky you just
> killed a zombie.
>
John - thanks for that, but it's not entirely clear to me.
What exactly do you mean by 'email the address(es)' - where to?

--
Neil




Posted by John Bokma on October 12, 2008, 12:07 pm
Please log in for more thread options



>
>>
>>> Hi Folks,
>>>
>>> Just came across this in server access log. Can anybody tell me
>>> what's likely to be going on with this.
>>
>> MS SQL injection attempt:
>> http://www.f-secure.com/weblog/archives/00001427.html
>>
>> Get the IP address from the log, type it after:
>>
>> http://www.spamcop.net/sc?track=
>>
>> and email the address(es) returned by spamcop. If you're lucky you just
>> killed a zombie.
>>
> John - thanks for that, but it's not entirely clear to me.
> What exactly do you mean by 'email the address(es)' - where to?

The attempt is done from an IP address, if you glue the address after the
URL above, you most likely get one or more email addresses (abuse@....).
Copy the line(s) from your access log, and email them to those addresses
with the request to: Remove the infected computer, which is being used for
SQL injections, from their network.

Most of the time this is done within a short time, and you might help
others that way.

--
John Bokma http://johnbokma.com/

AISE/AWW/SEO/web development forum: http://seo-expert-wiki.com/

Posted by Neil on October 12, 2008, 12:20 pm
Please log in for more thread options



>
>>
>>>
>>>> Hi Folks,
>>>>
>>>> Just came across this in server access log. Can anybody tell me
>>>> what's likely to be going on with this.
>>>
>>> MS SQL injection attempt:
>>> http://www.f-secure.com/weblog/archives/00001427.html
>>>
>>> Get the IP address from the log, type it after:
>>>
>>> http://www.spamcop.net/sc?track=
>>>
>>> and email the address(es) returned by spamcop. If you're lucky you just
>>> killed a zombie.
>>>
>> John - thanks for that, but it's not entirely clear to me.
>> What exactly do you mean by 'email the address(es)' - where to?
>
> The attempt is done from an IP address, if you glue the address after the
> URL above, you most likely get one or more email addresses (abuse@....).
> Copy the line(s) from your access log, and email them to those addresses
> with the request to: Remove the infected computer, which is being used for
> SQL injections, from their network.
>
> Most of the time this is done within a short time, and you might help
> others that way.
>


Right I've got you. Well I'm kicking myself. I never recorded the IP number
at the time. I did a lookup on it at the time and it was USA somewhere, but
didn't make a note of it. I've found out today that the access log isn't
archived (it is now) so there's no way I can trace it. I'll know better the
next time though.

Thanks for the info guys.
Neil





Posted by Neil on October 12, 2008, 12:46 pm
Please log in for more thread options



>
>>
>>>
>>>> Hi Folks,
>>>>
>>>> Just came across this in server access log. Can anybody tell me
>>>> what's likely to be going on with this.
>>>
>>> MS SQL injection attempt:
>>> http://www.f-secure.com/weblog/archives/00001427.html
>>>
>>> Get the IP address from the log, type it after:
>>>
>>> http://www.spamcop.net/sc?track=
>>>
>>> and email the address(es) returned by spamcop. If you're lucky you just
>>> killed a zombie.
>>>
>> John - thanks for that, but it's not entirely clear to me.
>> What exactly do you mean by 'email the address(es)' - where to?
>
> The attempt is done from an IP address, if you glue the address after the
> URL above, you most likely get one or more email addresses (abuse@....).
> Copy the line(s) from your access log, and email them to those addresses
> with the request to: Remove the infected computer, which is being used for
> SQL injections, from their network.
>
> Most of the time this is done within a short time, and you might help
> others that way.
>
Update:
Well I finally managed to track down the IP address. Have done as you
advise with spamcop and sent the message to the (offending) host. I'm not
sure if it's appropriate to publish the host identity so I'll not include it
here. However on the other hand the IP address may be useful to others so
they can block it. What do I do - do I post the IP address?

--
Neil



Similar ThreadsPosted
Re: Possible hack attempt ? October 11, 2008, 6:39 pm
form hack attempt August 24, 2006, 12:27 pm
Another hack attempt aimed at Mambo/coppermine combination November 4, 2006, 11:03 am
how to hack a DB February 28, 2005, 5:00 pm
Need an IE7 hack October 26, 2006, 12:20 pm
hack attempts? January 25, 2006, 8:28 am
Hack these bastards please. October 10, 2006, 9:08 pm
Hack question? May 4, 2007, 1:20 am
OT: The worlds worst phishing attempt April 10, 2005, 10:52 pm
hack ovh.bd2475 account February 10, 2007, 3:02 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap